How to Build a Cybersecurity Plan for Your Small Business
Learn how to build a cybersecurity plan for your small business with practical steps to protect data, reduce risks and prepare for cyber threats.
● Insights
How to Build a Cybersecurity Plan for Your Small Business
01
Assess Your Business's Cybersecurity Risks
Identify your most valuable data, understand where your vulnerabilities lie and prioritise the threats most likely to affect your business.
02
Create a Practical Cybersecurity Strategy
Build a plan that covers password security, employee training, software updates, backups, access controls and incident response procedures.
03
Review and Strengthen Your Defences Regularly
Cyber threats evolve constantly. Learn how to monitor your security, update your policies and ensure your business remains protected as it grows.
How to Reduce Cyber Risks in Your Small Business
If you’ve ever asked yourself, how do I create a cybersecurity plan for my small business?, you’re already asking the right question. Ransomware shows up in 88% of small business breaches, yet many small business owners still operate without a written cybersecurity plan. That gap between the threat and the preparation is exactly where attackers live, and they know it.
Many cybersecurity guides assume enterprise resources rather than the constraints of small businesses. They’re written for IT teams with dedicated budgets, specialized tools, and someone whose entire job is security. You’re the owner, the accountant, the customer service rep, and now apparently the CISO too. You need a plan that fits that reality, not a 60-page framework designed for a company with 500 employees.
This guide, produced by The Digital Resistance for small business owners across the United States, gives you a working cybersecurity plan you can act on today. No jargon. No technical background required. Just the steps that matter most, in the order that makes sense for a business your size.
Why small businesses are being targeted right now
The numbers are worth sitting with for a moment. Phishing accounts for 33 to 36% of confirmed small business breaches (Verizon Data Breach Investigations Report). Business email compromise causes $2.77 billion in annual losses and targets small businesses in 73% of cases (FBI IC3 Annual Report). Stolen or compromised credentials are the single most common entry point, appearing in 22% of all confirmed breaches.
According to SlashNext’s 2025 Phishing Intelligence Report, AI-generated phishing attacks increased 340% in 2025, and threat intelligence from the same period indicates that roughly 41% of small business incidents tracked in 2025 were AI-assisted. Attackers are scaling faster than most defenses can keep up with, and the financial consequences are severe: the average ransomware recovery cost for a small business runs between $638,000 and $1.5 million (Sophos State of Ransomware Report), and that figure doesn’t include the ransom itself.
The assumption that “we’re too small to be a target” is one of the most expensive beliefs a small business owner can hold. Attackers choose small businesses precisely because the defenses are usually thin, no dedicated IT team, weaker authentication, employees juggling multiple roles who are more likely to click a bad link under deadline pressure. One phishing email hitting the wrong inbox can trigger ransomware that shuts your operations down for days. A written, prioritized cybersecurity plan is your defense against that scenario.
How do I create a cybersecurity plan for my small business?
Creating a cybersecurity plan for your small business comes down to five practical steps: mapping your assets, locking down four foundational controls, training your team, writing a basic incident response plan, and pulling it all together with free tools. The sections below walk through each one in order. Start at the top and work your way through, you don’t need to complete everything in a single sitting.
Map what you have before you write a single policy
You can’t protect what you haven’t named. Before you write a single rule or policy, build a complete list of every device and account that touches your business data: laptops, phones, tablets, point-of-sale terminals, cloud storage accounts, payroll platforms, banking portals, and vendor portals. This asset inventory becomes the scope of your entire plan.
Next, identify the data that matters most. Customer payment information, employee records, contracts, banking credentials, and any regulated data in your industry all go on this list. For each asset, ask two questions: what is the realistic threat, and what is the business impact if that asset is compromised or lost? A compromised bank account matters more than a defaced website. Prioritize by business impact, not just by how likely an attack seems.
This exercise is your basic cyber risk assessment. The output is a one-page document that maps your assets, the likely threats against each, and the controls you’ll put in place. The Digital Resistance offers a free asset inventory and threat model template at thedigitalresistance.com to help you build this without starting from a blank page. Start there, and the rest of the plan builds naturally.
Four controls that stop most attacks without breaking your budget
You don’t need a large security budget to stop the most common attacks. Implement four foundational controls, in the right order, and make sure they’re actually working. These align with NIST’s small business cybersecurity guidance (NIST SP 1800-25) as a minimum viable control set for businesses with fewer than 50 employees.
1. Turn on multi-factor authentication for every account that matters
MFA is the single highest-return control available to a small business. It stops most credential-based account takeovers even when a password has already been compromised. Start with your email accounts, banking portals, cloud storage, VPN, payroll platforms, and any admin accounts. Many platforms include MFA at no additional cost, enabling it typically takes only a few minutes per account.
2. Enable automatic software updates and protect every device
Unpatched software is among the most common ways attackers get into small business systems. Enabling automatic OS and application updates closes known vulnerabilities with zero ongoing effort. Pair this with a business-grade antivirus or endpoint protection tool on every device, centrally managed if possible. Add a monthly calendar reminder to manually check anything that can’t auto-update, like older specialty software or legacy hardware.
3. Set up backups you can actually restore from
Use the 3-2-1 rule: three copies of critical data, on two different media types, with one stored offsite or in the cloud. A backup only counts if you’ve tested the restore. Schedule a quarterly restore drill so you know your backup works before ransomware forces the question. Tested backups are one of the most important defenses against ransomware (Sophos State of Ransomware Report). Without them, recovery means paying the ransom or starting from zero.
4. Restrict access to only what each person needs
Apply the principle of least privilege: each employee and each account should only have access to the systems and data they actually need to do their job. Review admin accounts and remove access that’s no longer needed, especially for former employees. This single step significantly limits the damage an attacker can do if they compromise one account.
Turn your employees into your first line of defense
Phishing is the most common attack entry point for small businesses, and AI has made it significantly more dangerous. Attackers now generate convincing, personalized emails at scale. The old advice about looking for bad spelling no longer applies. Your employees need an updated, practical set of warning signs to watch for.
Train your team to recognize these red flags:
- Unexpected urgency or pressure to act immediately
- Requests for login credentials, wire transfers, or gift card purchases
- Sender domains that look slightly off (suppIier.com instead of supplier.com)
- Links where the displayed text doesn’t match the actual destination
- Requests from “executives” asking for unusual actions outside normal processes
Teach one simple verification rule: any request involving money, account access, or sensitive data gets confirmed through a separate channel before any action is taken. Always verify using a phone number from a known, trusted source, not the contact information in the suspicious email itself. A quick call to a known number stops most business email compromise attacks before they cause damage.
Frequency matters more than depth. A single annual training session doesn’t build habits. Short monthly reminders and periodic simulated phishing exercises are far more effective. CISA and NIST both offer free phishing awareness resources at their respective websites. Open-source tools like GoPhish and platforms like PhishDrills let you run simulated phishing campaigns for your team at low or no cost, though free tiers may carry some limitations. The goal isn’t to punish employees who click on a test email. The goal is to build a team that reports suspicious activity without fear, because that report often stops an attack before it escalates.
Write a basic incident response plan before you need one
An incident response plan answers one question: when something goes wrong, who does what and in what order? Writing this plan before an incident happens is the difference between a managed response and a panicked scramble that makes the damage worse.
Every small business incident response plan should follow this sequence: Detect, Triage, Contain, Eradicate, Recover, Notify, Review. The most critical rule in that sequence is to contain first and investigate second. If a device or account is suspected compromised, disconnect it from the network and disable the account before you try to understand what happened. Document everything as you go, timestamps, affected systems, and every action taken. This record matters for insurance claims, regulatory requirements, and the post-incident review.
Define roles before an incident happens. Who is the incident lead? Who is the backup if that person is unavailable? What is your IT provider or managed service provider’s emergency contact? Many cyber insurance policies require notification within 24 to 72 hours of discovery, check your policy language now rather than during the incident. Know which external parties need to be notified: customers if their data was exposed, FBI IC3 for cybercrime reporting, and any state regulators that apply to your industry. All 50 U.S. states have data breach notification laws, and most require notice within 30 to 60 days of discovery (National Conference of State Legislatures). Knowing your obligations in advance keeps a bad situation from becoming a compliance crisis on top of a security crisis.
Free tools, templates, and a community built around your defense
Building out your cybersecurity plan doesn’t have to start from a blank page, and most of the tools you need won’t cost anything. Federal agencies have invested heavily in free resources specifically for small businesses.
Three resources worth bookmarking right now:
- FCC Small Biz Cyber Planner 2.0:an interactive online tool that generates a customized cybersecurity plan based on your business type and size. Free, no technical background required, and the output is a practical planning guide you can act on immediately.
- CISA Small Business Resources: free vulnerability scanning, printable fact sheets, and the Cyber Resilience Review self-assessment. CISA also offers a free SMB Toolkit with starter steps and hands-on resources tailored to businesses without IT teams.
- NIST Small Business Cybersecurity Corner: over 70 free resources including quick-start guides, tip sheets,planning workbooks, and case studies. Downloadable directly from the NIST site.
These federal tools give you the framework. The real work is tailoring that framework to your business, your assets, and the risks that are actually relevant to you. That’s where a community makes the difference.
The Digital Resistance is built specifically for small business owners and non-technical Americans who are building their defenses without an IT team. At thedigitalresistance.com, you can download practical templates, including an asset inventory, an incident response plan, and a complete SMB cybersecurity checklist, and connect with other entrepreneurs going through the same process. The community shares threat warnings, tested tools, and real-world lessons from businesses that have been through an incident and rebuilt stronger. Solo business owners may not have an IT department, but they can have a community that functions like one.
Your cybersecurity plan starts today
Creating a cybersecurity plan for your small business doesn’t require a technical background or a large budget. It requires a clear starting point and the decision to act before something goes wrong. Work through the steps in this guide: build your asset inventory, implement the four foundational controls, train your team on current phishing tactics, define roles in your incident response plan, and use the free tools available to tie it all together.
Start with the asset inventory. Download the free SMB cybersecurity checklist from The Digital Resistance, list every device and account that touches your business data, and work through each section of this guide in order. The plan doesn’t need to be perfect to be useful. A written, working plan that you refine over time is exponentially more effective than no plan at all.
Every small business that builds a plan makes the whole network harder to breach. This is collective defense, and that decision is yours to make right now.
Headquarter
12 Belmont, BathUnited Kingdom
Telephone
+447707329924

